ion_system_heap_destroy_pools frees the pool, but
does not invalidate the pointer. This can result in
a double free if ion_system_heap_create_pools fails,
and then causes ion_system_heap_create to call into
ion_system_heap_destroy_pools again from the error
path. This can happen in ion_system_heap_create when
one of the secure pool creation fails.
Change-Id: Ic73ca78722aa5a575cc4dd7c1caa560b518094f2
Signed-off-by: Vinayak Menon <vinmenon@codeaurora.org>
[haggertk: Backport to 3.4/msm8974]
CVE-2018-11987
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Change-Id: Ia634b790661089ad01aca8e5975984435463d148
Signed-off-by: Daniel Rosenberg <drosen@google.com>
Bug: 34276203
Fixes: Ibc36bc4405788ed0fea7337b541cad3be2b934c0
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
event->handle pointer can be used after free due to
the race condition between kgsl_sync_callback and
kgsl_sync_fence_async_cancel.
Protect the event->handle with a spinlock to
avoid concurrent access issues.
Bug: 62949902
Change-Id: I3719e401af9ece82ac68b72f2aef784c7fdc1104
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
CVE-2017-11092
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This separates the kref for ion handles into two components.
Userspace requests through the ioctl will hold at most one
reference to the internally used kref. All additional requests
will increment a separate counter, and the original reference is
only put once that counter hits 0. This protects the kernel from
a poorly behaving userspace.
Bug: 34276203
Change-Id: Ibc36bc4405788ed0fea7337b541cad3be2b934c0
Signed-off-by: Daniel Rosenberg <drosen@google.com>
Git-repo: https://android.googlesource.com/kernel/msm/
Git-commit: 20abfcc16884a5af973a5e91dd013ddd789c44f4
[d-cagle@codeaurora.org: Resolve style issues]
Signed-off-by: Dennis Cagle <d-cagle@codeaurora.org>
CVE-2017-0564
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
When allocating userspace memory keep reference to memory
allocation till it is completely initialized and info is send back
to userspace
Bug: 32938443
CRs-Fixed: 2029113
Change-Id: Id72c82bf98c094ecbd4722813c732a998dcbb188
Signed-off-by: Tarun Karra <tkarra@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
Signed-off-by: Dennis Cagle <d-cagle@codeaurora.org>
CVE-2017-8262
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Make the various timeout values HZ agnostic by using the proper
macros and values instead.
Change-Id: I906b948657c8873518042c7465272c98c5391e59
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
Reorder our sync_fence_install() calls to happen after
all possible failures so that error cleanup will be
correct.
CRs-Fixed: 1081855
Change-Id: I0e7bb459f2acc010446ac5e5b3b72c8b16cce079
Signed-off-by: Jeremy Gebben <jgebben@codeaurora.org>
Signed-off-by: Sudeep Yedalapure <sudeepy@codeaurora.org>
The format specifier %p can leak kernel addresses
while not valuing the kptr_restrict system settings.
Use %pK instead of %p, which evaluates whether
kptr_restrict is set.
Change-Id: I0778e43e0a03852ca2944377256a7b401586a747
Signed-off-by: Divya Ponnusamy <pdivya@codeaurora.org>
Signed-off-by: Sudeep Yedalapure <sudeepy@codeaurora.org>
In adreno_perfcounter_query_group() make sure to cast the user passed
count to an unsigned int before comparing it to the group count.
Otherwise the user count could be interpeted as a signed int and
hilarity ensues.
Change-Id: Ic0dedbad825f5b3fd4434f9b9f6d4d308206c0d9
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
In _kgsl_sharedmem_page_alloc():
- Make len of type size_t to be in line with size.
- Check for boundary limits of requested alloc size before honoring.
Change-Id: I8b9e225e515a0f31593df6f4cad253236475d0ae
Signed-off-by: Rajesh Kemisetti <rajeshk@codeaurora.org>
If we add the mem entry pointer in the process idr and rb tree
too early, other threads can do operations on the entry by
guessing the ID or GPU address before the object gets returned
by the creating operation.
Allocate an ID for the object but don't assign the pointer until
right before the creating function returns ensuring that another
operation can't access it until it is ready.
CRs-Fixed: 1002974
Change-Id: Ic0dedbadc0dd2125bd2a7bcc152972c0555e07f8
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
The pagetable.entries statistics should be incremented by 1
and not the size of the entire mapping.
CRs-Fixed: 911514
Change-Id: Ic9acb6a43a76ee0c429c439e60cbd2a6846647db
Signed-off-by: Harshdeep Dhatt <hdhatt@codeaurora.org>
Sometimes the user mode driver assigns a timestamp and goes to all
the work of constructing a command before it discovered it doesn't
need to be executed on the GPU. If that happens the driver can
set the MARKER bit and let the kernel figure how to keep timestamps
moving forward in a linear fashion.
If no commands are ahead of the marker the dispatcher will discard
it in software (and update the timestamps accordingly). If there
are command ahead of it the marker will wait patiently for those
to expire. If new commands come in after the marker the marker
can be dispatched with NOPs in place of the IBs so the timestamp
accounting stays correct.
Change-Id: Ic0dedbada4006e3cf9d4698a419be93b1620d35a
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
There could be a race condition if a thread is adding an event while
another thread is processing events. Say that thread A is adding an
event and thread B is processing events. A could read the timestamp
and see that it isn't retired yet and wait for the spinlock to add
it to the list. Meanwhile the timestamp gets retired and the retire
thread takes the spinlock first and proceses the list. End result
is the event for the newly expired timestamp gets added to the list
after the timestamp retires. If there are no subsequent events then
the lame duck event will just sit there.
Avoid this race condition by taking the spinlock before considering
the timestamp. This serializes the two threads ensuring that a new
event cannot be added after the same timestamp is retired.
The race condition could still fail with the locks in the right place
if different cores got different timestamp values so add the correct
barriers to the memory read/write functions to ensure that all cores
read the same value at the same time.
Change-Id: Ic0dedbad02e7aeeaab48373ab28f4dc9cce50db2
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
The old GPU event model was pretty heavy weight. It walked a lot
of issues while holding the mutex and was generally not very
flexible or scalable.
The new design introduces event groups. Event groups have a list of
common events with a local lock. Each context has a default event
group and the device adds a few more for global events and IOMMU events.
Each event group is processed when timestamps expire and the expired
events are scheduled on a workqueue. We never need to take the device
mutex in any of the event code and we have the flexibility to deal with
both global and per-context timestamps in a reasonably generic manner.
Speed is a premimum at every step of the process, so we use RCUs for
the global group list, a new kmem cache for the event structs and
generally go out of our way to avoid blocking in rendering threads
even a little bit.
Change-Id: Ic0dedbad02eec7c75258e6787543b79d4b8b3394
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
Allow users to send in a list of all memory that is used
in the command submission. Store the memory list in the
command batch so we can do smart things with it.
Change-Id: Id81dcf25ffacf2848eee37c73699683ace48dbf9
Signed-off-by: Carter Cooper <ccooper@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
Split out the context and command batch flags into separate piles.
In reality it is more like a venn diagram with some context
exlusive bits some cmdbatch exclusive bits and some shared bits.
The object of all this is to increase the available pool of exclusive
command batch flags and keep from using up all of the context bits
too. We still have to be careful for future shared bits so not all of
the unused field is up for grabs for the command batch but we
certainly have increased our options.
Change-Id: Ic0dedbadac4a12b712c911760f83da3436550bcb
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
Sometimes the user driver has reason to force the command preamble
to run on every submit and not just when the context is switched.
Support KGSL_CONTEXT_CTX_SWITCH for both an entire context or
just a single submission.
Change-Id: Ic0dedbad52fae5fd6ca975ea7eb9f1002e0815ed
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
If you run aggressive memory operations long enough, eventually you
will notice that the KGSL memory statistics will explode up into the
3G range. This is a race condition on the statistics math which ends up
going negative in certain cases. Turning the statistics variables into
atomics should solve the problem once and for all. ONCE AND FOR ALL.
Change-Id: Ic0dedbad61762d667550c22190c4f9d0b453829b
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
Marker commands may not be submitted to RB but
create room in context queue on expiry which is
left uncounted. If there are too many markers
commands from a specific context then context
queue eventually gets full but wakeup is never
called for sleeping threads.
Wake up the snoozing threads when there is room
in the context queue rather than based on the
condition of real submissions from the context.
CRs-fixed: 783187
Change-Id: I0cb0002d7b641071a45d46ae50ce9f23f37b0fab
Signed-off-by: Sunil Khatri <sunilkh@codeaurora.org>
Signed-off-by: Anupam Sakargayan <asakarga@codeaurora.org>
It turns out that having lots of spurious threads causes race
conditions. Who knew? Instead of spawning a new high prority
thread just bump the priority of the current thread up
while adreno_start is running.
Change-Id: Ic0dedbadf65da11c800578c8769ae844f010e925
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
kgsl_cancel_event must be called with device->mutex
otherwise it will cause a BUG_ON in kgsl_cancel_event
kgsl_cmdbatch_destroy will call kgsl_cancel_event, hence added
device->mutex lock/unlock wherever kgsl_cmdbatch_destroy is called
Change-Id: I9b9959236d6be0d80987279a64a0715363229f7b
Signed-off-by: Anupam Sakargayan <asakarga@codeaurora.org>
kgsl_cancel_event must be called with device->mutex
otherwise it will cause a BUG_ON in kgsl_cancel_event
CRs-fixed: 761881
Change-Id: I904f3321edaa07505077fe53d82e09f9200e3781
Signed-off-by: Anupam Sakargayan <asakarga@codeaurora.org>
Ignore signals when waiting for ringbuffer timestamp since
the wait needs to complete regardless of whether the process
got a signal. Also, increase the wait timeout for context
detachment to 30s instead of 10s. Large IB's can take longer
than 10s to retire and if a hang happens then recovering from
the hang and completing the long IB's will take much longer
than 10s, bump this timer to 30s which should be sufficient
for the context's commands to retire even if hang happens.
Conflicts:
drivers/gpu/msm/adreno_drawctxt.c
drivers/gpu/msm/adreno_ringbuffer.c
CRs-Fixed: 718284
Change-Id: I54589c9ec48da3f87ccc60c85451daac7e9a22bd
Signed-off-by: Shubhraprakash Das <sadas@codeaurora.org>
Signed-off-by: Anupam Sakargayan <asakarga@codeaurora.org>
If an IB cannot be added to the snapshot list, that's no reason to
stop dumping the object that uses it. Continuing further will make
sure that all possible data is dumped into the snapshot, and make
it available for offline use.
Change-Id: Ia541510754a9919838e7fc337fa3f2515c6f0f05
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
adreno_drawctxt_dump is called from within timer context and hence
this function cannot sleep. But it needs exclusive access to its
cmdqueue. Therefore, changing the drawctxt mutex to spinlock.
Change-Id: I180c3a4703ffc51bb9929df44dae862e2e6a432b
Signed-off-by: Harshdeep Dhatt <hdhatt@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
Add a wrapper kgsl_sync_fence_log around sync_fence_log.
This helps get rid of compilation error if CONFIG_SYNC is
not defined.
CRs-Fixed: 748003
Change-Id: I20d9c0e4b449cb2352274b5f4062300d5562bae6
Signed-off-by: Harshdeep Dhatt <hdhatt@codeaurora.org>
Android native fences have the annoying habit of disappearing before
we are done querying them. Instead of reaching into the fence struct
to find the name for the fence, copy it off at init time and use that
for our various logging needs.
CRs-fixed: 743080
Change-Id: Ic0dedbad21eddf71d5e8a086eea09c5201660f0a
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
The point is to add syncpoint tracepoints to trace the point at
which syncpoints are created and expired.
Change-Id: Ic0dedbadb9cd913c2949e9786c84f7517b8e0581
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
Active count is a variable that is mutex protected. When waiting
for this variable the value should be verified with mutex held.
Change-Id: Iee8c43cacd22f05b03a350f3b46b3e5a9fff5c63
Signed-off-by: Shubhraprakash Das <sadas@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
Track the last timestamp that each draw context has submitted to
the ringbuffer. This complete the picture for the draw context
dump:
kgsl-3d0: context[13]: queue=165, submit=115, start=101, retire=100
here, timestamp 165-116 are on the queue, 115-102 are on the
ringbuffer, 101 is in the GPU and 100 and older have been retired.
If we get a fence timeout with this data we can easily see where the
fence timestamp is in the pipeline.
Change-Id: Ic0dedbadf54c1714296149af02b6938eef375d50
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
The code was being very generous in giving the user the ability to
align GPU objects on 4GB boundaries. Cut the restriction down to
32MB which is still pretty generous but within the realm of
possiblity (especially for a 32 bit GPU). While we are at it fix
a bug in the page_alloc code that was accidently resetting the
alignment to the alloc page size. The alignment cannot be _less_
than the max page_alloc size but there certainly isn't any reason
why you couldn't specify a larger alignment if you so wished.
Change-Id: Ic0dedbadebd4c6fd98e3bf2f3d6d5bb924223157
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
Attempt to detect recursion in the sync fence logging mechanism
whereby a syncpoint is waiting for a fence that ends up waiting for
the same context that owns the syncpoint.
CRs-Fixed: 744197
Change-Id: Ic0dedbadb4207ad5823f882b20007914bd80c391
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
Dump sync fence info of a fence for which a KGSL context is waiting
for more than 5 seconds. This info will help detect if there is
a possible gpu syncpoint deadlock.
Change-Id: I53282ce08e716cfdb44ca448f880e84816dc4ded
Signed-off-by: Harshdeep Dhatt <hdhatt@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
Add a callback to get notification of timeouts on fences
that we own and use that to dump additional information.
Change-Id: Ic0dedbadec6af50cc8c741484a5547ae0ca92a83
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
When cmdbatch timer expires, fence address at log entry is incorrect.
Hence sync_fence & kgsl logs don't match for timed out fence pointer.
This is inconvenience to debug fence timeouts. Log correct fence
address if valid.
Change-Id: I7cead43989d5551e9b2d5f6eefb8baacd37bd69b
Signed-off-by: Ananta Kishore K <akollipa@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>
When creating a new fence immediately signal the timeline if the target
timestamp has already expired and don't create a new GPU event. This
cuts down on the number of events being fired for already expired
timestamps and removes the brief delay for the event to go out and
immediately come back.
Change-Id: Ic0dedbadc0512977f662bda5fdb4c4d3db7bd51f
Signed-off-by: Jordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: Lynus Vaz <lvaz@codeaurora.org>